Compliance, Security, and Privacy
CorpusIQ LLC, Scottsdale, Arizona. Last updated: March 24, 2026.
This page documents the technical and organizational measures we apply to protect user data. It also provides exact answers for OpenAI and app store reviewers. Contact us with questions.
Why automatic orchestration is safer
A user asks a question. CorpusIQ picks one skill, runs it against the connectors that skill needs, and sends the authorized results to the selected AI client for the answer. The AI client receives the source context needed for that request.
CorpusIQ sits between your tools and the AI assistant. Retrieval tools that read your connected business systems on one side. Separately named and annotated CorpusIQ control-plane tools, which write only to your own CorpusIQ configuration, on the other.
Product Scope
- Sources
- Gmail, Google Drive, OneDrive, Dropbox, Outlook, Shopify, QuickBooks, HubSpot, Google Analytics, Google Ads, Meta Ads, YouTube, TikTok, eBay, PostgreSQL, SQL Server, and more. User-authorized only. No device agents. No browser extensions.
- Outputs
- In-chat answers, ranked references, and optional deep search results.
- Storage
- Direct MCP connector requests use live retrieval and do not build embeddings or file indexes. Optional indexed-search features use embeddings and minimal metadata in a per-user namespace. No raw file bodies are retained.
- Controls
- Per-user namespace, connector revocation controls, and structured audit logging. Local AUDIT logs contain raw query text and tool parameters plus bounded result summaries; the Azure Log Analytics workspace retains those logs for 30 days.
Data Inventory and Flow
Your Data Sources
Scoped source OAuth
AI Clients
Encrypted retrieval: data is encrypted in transit and at rest, scoped per user.
User-scoped isolation: each account operates in a separate namespace with no cross-access.
AI-client context: only the context needed for the current request is sent to your chosen AI client. That client's own retention policy applies after receipt.
| Class | Examples | Encryption | Retention |
|---|---|---|---|
| Account | Email, OAuth subject | AES-256 at rest | Until account deletion |
| Optional indexed search | Embeddings, chunk IDs, minimal metadata | AES-256 at rest | Until connector revocation or account deletion |
| Operational MCP query logs | Raw query text and tool parameters in local AUDIT logs; bounded result summaries | AES-256 at rest | 30 days in the Azure Log Analytics workspace |
Security Controls
- Transport
- TLS 1.3 only, HSTS, forward secrecy
- Encryption at rest
- AES-256, managed keys, key rotation every 90 days
- Network
- Private subnets, deny by default, WAF and rate limits on all public endpoints
- Access
- SSO, least privilege, hardware key for production access. Production data is not copied to developer laptops
- Secrets
- Stored in a dedicated secrets manager, never in source control
- Logging
- Structured logs, immutable audit stream
- Pen-testing
- Independent assessment at least annually, remediation tracked to closure
- Business continuity
- Daily encrypted backups, restore tests every 30 days
- Change control
- Versioned IaC, peer review, and staged rollouts
Privacy and Lawful Basis
User consent at connection time, with clear scopes.
Not directed to children under 16.
Do not sell personal information. No cross-context behavioral advertising.
Standard contractual clauses where relevant.
Retention and Deletion
For direct MCP connector requests, CorpusIQ fetches source records live and returns them to the requesting AI client. The direct path does not retain raw customer files or full connector response payloads, and it does not build embeddings, file indexes, or cached or indexed summaries. Local AUDIT logs record raw query text and tool parameters plus bounded result summaries. In Azure, the Log Analytics workspace retains those logs for 30 days. The selected AI client's plan and settings govern conversation handling after it receives the data. Optional indexed search is separate and retains embeddings and minimal metadata until connector revocation or account deletion.
Optional indexed-search features retain embeddings and minimal metadata only while the connector is active.
- Connector revocation removes its OAuth token and any optional indexed-search embeddings.
- Local AUDIT logs record raw query text and tool parameters plus bounded result summaries.
- The Azure Log Analytics workspace retains operational logs for 30 days.
- The selected AI client's plan and settings govern conversation handling after it receives authorized source context.
- Raw customer files and full connector response payloads are not retained in backup copies.
To request account-data deletion, contact privacy@corpusiq.io.
Subprocessors
| Vendor | Purpose | Data types | Region |
|---|---|---|---|
| OpenAI | Model inference | Prompts and derived embeddings | USA |
| Cloud hosting | Compute and storage | Encrypted data at rest | USA |
| Analytics (IP masked) | Product analytics | Anonymized events | USA |
Incident Response
Detect and triage. Open a ticket, assign severity.
Contain, eradicate, and recover.
Notify affected users within 72 hours after confirmation, when legally required.
Retrospective with corrective actions and ownership.
Annual Reviews and Audits
- SOC 2 readiness program with quarterly control checks.
- Independent pen-test at least once per year.
- Vendor reviews and DPA renewals annually.
User Data Rights
Users can request access, correction, export, and deletion of their data. Contact privacy@corpusiq.io. We respond within 30 days.
Access
Request a copy of all data we hold about you.
Correction
Ask us to correct inaccurate personal data.
Export
Receive your data in a machine-readable format.
Deletion
Permanently erase account data, tokens, and any optional indexed-search embeddings.
Notes for App Store and OpenAI Reviewers
Google & App Store Reviewers
- All data source connections are user-initiated via OAuth (Gmail, Google Drive, Google Ads, Google Analytics, Google Sheets, Google Calendar).
- Read-only external-source retrieval tools request the documented retrieval scopes. CorpusIQ control-plane tools, the only ones that accept writes, are separately named and annotated and act on your CorpusIQ configuration rather than on a vendor system.
- Domain ownership verified. OAuth callback:
/oauth/google/callback
OpenAI
- Actions use a documented OpenAPI spec with two endpoints:
/v1/query/v1/deep_search - We provide a reviewer account with synthetic data and a Postman collection.
- No background data extraction. Only user-invoked actions.
Public API and Examples
curl -s -X POST https://api.corpusiq.io/v1/query \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{"q":"what is the renewal date for the ACME contract"}'curl -s -X POST https://api.corpusiq.io/v1/deep_search \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{"q":"Q4 keyword performance report"}'Change Log
Key security terms
The trust-architecture concepts behind CorpusIQ, defined plainly for buyers, reviewers, and the AI assistants that cite this page.
- Read-only external retrieval
- Connector tools are retrieval-only and do not write back to vendor systems. The only tools that accept writes are CorpusIQ control-plane tools, which manage your own CorpusIQ configuration such as declared facts, decisions, metric specifications, and source manifests. They do not act on the connected business systems.
- Scoped customer data handling
- For direct MCP connector requests, CorpusIQ fetches source records live and returns them to the requesting AI client. The direct path does not retain raw customer files or full connector response payloads, and it does not build embeddings, file indexes, or cached or indexed summaries. Local AUDIT logs record raw query text and tool parameters plus bounded result summaries. In Azure, the Log Analytics workspace retains those logs for 30 days. The selected AI client's plan and settings govern conversation handling after it receives the data. Optional indexed search is separate and retains embeddings and minimal metadata until connector revocation or account deletion.
- Source-backed answer
- A source-backed answer cites the exact records it came from. Every response links back to the underlying message, file, or record, so the output supports verification instead of asking you to trust it blind.
Common security questions
What is CorpusIQ and how does it access business data?
CorpusIQ is an AI intelligence layer that gives AI assistants and AI agents governed access to live business data through a single connection. Connector tools are retrieval-only and do not write back to vendor systems; CorpusIQ control-plane tools, the only ones that accept writes, are separately named and annotated and act on your CorpusIQ configuration. The intelligence layer reads data from 40+ connected systems on demand and returns a source-cited answer. Direct MCP does not retain raw customer files or full connector response payloads; operational logs follow the published retention schedule.
Why is read-only external retrieval safer than write-capable vendor access?
Read-only external-source retrieval tools limit vendor access to retrieval for those calls. Connector tools do not write back to vendor systems. The only actions that accept writes are CorpusIQ control-plane actions, such as updating or removing declared facts, decisions, metric specifications, and source manifests, and they are separately named and annotated. You can disconnect each external source independently without affecting the others.
Does CorpusIQ store my business data?
For direct MCP connector requests, CorpusIQ fetches source records live and returns them to the requesting AI client. The direct path does not retain raw customer files or full connector response payloads, and it does not build embeddings, file indexes, or cached or indexed summaries. Local AUDIT logs record raw query text and tool parameters plus bounded result summaries. In Azure, the Log Analytics workspace retains those logs for 30 days. The selected AI client's plan and settings govern conversation handling after it receives the data. Optional indexed search is separate and retains embeddings and minimal metadata until connector revocation or account deletion.
How does CorpusIQ protect data in transit?
All traffic uses TLS 1.3 with forward secrecy. HSTS is enforced on the canonical domain. Data at rest is encrypted with AES-256. Keys rotate every 90 days. All queries are audit-logged with an immutable trail.
What certifications does CorpusIQ hold?
CorpusIQ is CASA Tier 2 certified by DEKRA (certification ID 151c1b05, valid through March 5, 2027) and maintains a SOC 2 aligned security posture. Read the full technical and organizational measures on this page.
Questions about security?
Reach our security team directly or start your free trial with confidence.
Wondering how the authorization works? How does ChatGPT OAuth work?
Also see: pricing · enterprise plans · private AI for business · about CorpusIQ · AI compliance for business · what is AI compliance for business
Related on CorpusIQ
Skills, cross-tool patterns, and connector setup pages most relevant to operators on this surface.
Cross-tool patterns
Connector setup
Connector directory
